Panorays’ Smart Questionnaire is fully customizable, allowing each organization to create questionnaires that best align with its security, compliance, and risk management needs.
With Smart Questionnaire, you send only relevant questions to each supplier, based on the specific processes and activities they perform for your organization. This reduces unnecessary questions for suppliers and improves the quality of the responses you receive.
🔍 How It Works
Smart Questionnaire dynamically adjusts which questions are sent to each supplier based on:
Defined relationships
Supplier processes and activities
Selected questionnaire mappings
This ensures that suppliers are evaluated only on controls that are relevant to their engagement with your organization.
➕ Custom and Standardized Questionnaires
In addition to fully custom questionnaires, Panorays supports a variety of standardized industry questionnaires directly within the platform.
These questionnaires can be:
Edited
Mapped to relevant relationships
Combined with custom questions
All questionnaires listed below are available to Panorays customers at no additional cost.
📌 Available Questionnaires
🛡️ Panorays Best Practice Questionnaire
Developed by Panorays security experts, this questionnaire is designed to address multiple regulations and security frameworks, with a strong emphasis on ISO 27001.
Questions are mapped based on processes and activities, enabling evaluators to send only relevant questions to each supplier.
🛡️ Standardized Information Gathering (SIG)
The SIG questionnaire is a comprehensive repository of third-party information security and privacy questions, indexed to multiple regulations and control frameworks.
It is widely used for vendor risk assessments, with more than 15,000 active users.
Panorays is a licensed partner of Shared Assessments, allowing customers to use the SIG questionnaire within the platform.
☁️ Cloud Security Alliance CAIQ
The Consensus Assessments Initiative Questionnaire (CAIQ) focuses on cloud security.
It includes yes/no questions designed to assess a cloud provider’s compliance with the Cloud Controls Matrix (CCM), the Cloud Security Alliance’s cybersecurity framework for cloud environments.
⚡ Incident Questionnaire
Incident questionnaire was developed by the Panorays security team following high-impact cybersecurity incidents. These questionnaires help organizations assess the potential impact of specific breaches on their third-party ecosystem.
Israel National Cyber Directorate (INCD)
The INCD questionnaire includes 11 security controls related to web hosting and storage services, covering areas such as:
Access control
Endpoint and server protection
Perimeter protection
Monitoring and logging
Secure development
Cloud environments and data protection
💡 Tips / Important Notes
Standard questionnaires can be edited and combined with custom questions
Mapping questionnaires to relationships improves accuracy and response quality
Targeted questionnaires reduce supplier fatigue and follow-ups